HT TECH wants to start sending you push notifications. Click allow to subscribe

An Xbox bug could have let hackers link gamer tags with the players’ emails

This particular Xbox bug could have been exploited by playing around a browser’s developers console and editing a cookie field.

By: HT TECH
Updated on: Aug 21 2022, 00:10 IST
Microsoft did not classify this bug as “worthy of a monetary reward because the bug couldn't be used to hijack Xbox”, the bug could have allowed hackers to link any Xbox gamer tag to a gamer's real email address. (Pixabay)

Microsoft has patched a bug in the Xbox website that could have allowed hackers to link Xbox gamer tags (usernames) with the users’ email addresses. The vulnerability was reported to Microsoft through their Xbox bug bounty program.

One of the security researchers, Joseph “Doc” Harris, who reported the issue to Microsoft, shared his findings with ZDNet. Harris said that the bug was located on enforcement.xbox.com, the web portal where Xbox users “go to view strikes against their Xbox profile” and also file appeals if they feel “they have been unfairly reprimanded for their behaviour on the Xbox network”.

You may be interested in

Mobiles Tablets Laptops
7% OFF
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
₹148,900₹159,900
Buy now
28% OFF
Samsung Galaxy S23 Ultra 5G
  • Green
  • 12 GB RAM
  • 256 GB Storage
₹107,999₹149,999
Buy now
Google Pixel 8 Pro
  • Obsidian
  • 12 GB RAM
  • 128 GB Storage
₹106,998
Check details
Apple iPhone 15 Plus
  • Black
  • 6 GB RAM
  • 128 GB Storage
₹87,900
Check details
27% OFF
Microsoft Surface Studio A1Y 00022
  • Platinum Silver
  • 16 GB LPDDR4X RAM
  • 512 GB SSD
₹179,990₹245,900
Buy now
7% OFF
Microsoft Surface Pro 8 8PV 00029
  • Graphite Black
  • 16 GB DDR4 RAM
  • 256 GB SSD
₹139,999₹149,999
Buy now
47% OFF
Microsoft Surface 4 5UI 00049
  • Platinum Silver
  • 8 GB DDR4 RAM
  • 256 GB SSD
₹98,000₹186,500
Buy now
28% OFF
Microsoft Surface Pro 7 M1866 VDH 00013
  • Platinum
  • 4 GB LPDDR4X RAM
  • 128 GB SSD
₹74,000₹102,990
Buy now
34% OFF
Xiaomi Pad 6
  • Mist Blue
  • 6 GB RAM
  • 128 GB Storage
₹26,299₹39,999
Buy now
55% OFF
Lenovo Tab M10 5G
  • Abyss Blue
  • 6 GB RAM
  • 128 GB Storage
₹20,999₹47,000
Buy now
32% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹19,749₹28,999
Buy now
Honor Pad X9
  • Gray
  • 4 GB RAM
  • 128 GB Storage
₹14,999
Check details

Once users log into this website, the Xbox Enforcement site creates a cookie file in their browser with details about the web session. This is done for easier log in the next time and users do not have to re-authenticate details when they log in again.

Also Read: PS5 users are facing a bug that’s preventing them from downloading games, apps

Harris told ZDNet that Xbox Enforcement’s cookie file included an Xbox user ID (XUID) field that was unencrypted. This XUID field could easily be edited and replaced with the XUID of a test account as Harris demonstrated with tools that come on all modern browsers. This test account was one that Harris had created for the Xbox bug bounty program.

"Tried replacing the cookie value and refreshing, and suddenly I was able to see other (users’) emails," Harris told ZDNet in an interview. He also shared a video of the bug:

Microsoft fixed this bug by encrypting the XUID.

A Microsoft spokesperson said in an email that the fix was deployed on the server-side and added that there are no other steps that users need to take themselves to be protected.

Harris has pointed out that no other Xbox subdomain suffers from the same bug.

According to reports, a security analyst working for Microsoft's Security Response Center said the bug wasn't covered by the Xbox bug bounty program, but Microsoft agreed to feature Harris on their Bug Bounty Hall of Fame as a contributor.

Also Read: Microsoft’s latest patch fixes more than 100 vulnerabilities

Microsoft did not classify this bug as “worthy of a monetary reward because the bug couldn't be used to hijack Xbox”, the bug could have allowed hackers to link any Xbox gamer tag to a gamer's real email address.

Linking email accounts to gamers' real-world identities has led to instances of harassment. The fact that most gamers use the same email address for most of their online accounts also helps hackers a lot as is seen in this tweet -

Catch all the Latest Tech News, Mobile News, Laptop News, Gaming news, Wearables News , How To News, also keep up with us on ,Twitter, Facebook, , and Instagram. For our latest videos, subscribe to our YouTube channel.

First Published Date: 27 Nov, 17:20 IST
Tags:

Sale

Mobiles Tablets Laptops
4% OFF
Samsung Galaxy S24 Ultra
  • Titanium Black
  • 12 GB RAM
  • 256 GB Storage
₹129,999₹134,999
Buy now
7% OFF
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
₹148,900₹159,900
Buy now
13% OFF
Xiaomi 14
  • Matte Black
  • 12 GB RAM
  • 512 GB Storage
₹69,999₹79,999
Buy now
11% OFF
Apple iPhone 15 Plus
  • Black
  • 6 GB RAM
  • 128 GB Storage
₹79,800₹89,900
Buy now
57% OFF
Lenovo Tab M10 5G
  • Abyss Blue
  • 6 GB RAM
  • 128 GB Storage
₹19,999₹47,000
Buy now
28% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹17,999₹24,999
Buy now
20% OFF
Samsung Galaxy Tab S9 5G 256GB
  • Graphite
  • 8 GB RAM
  • 256 GB Storage
₹86,999₹108,699
Buy now
28% OFF
realme Pad 2 WiFi
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹17,999₹24,999
Buy now
23% OFF
Infinix INBook X1 Neo XL22 Laptop Intel Celeron Quad Core 8 GB 256 GB SSD Windows 11
  • Blue
  • 4 GB RAM
  • 128 GB SSD
₹22,990₹29,990
Buy now
28% OFF
Asus ROG Strix G17 G712LU EV078T Laptop
  • Blue
  • 16 GB RAM
  • 1 TB SSD
₹81,990₹113,990
Buy now
40% OFF
Samsung Galaxy Book Go Laptop
  • Silver
  • 4 GB RAM
  • 128 GB SSD
₹28,690₹47,990
Buy now
22% OFF
Asus ROG Strix G15 G513RC HN085WS Laptop
  • Electro Punk
  • 16 GB RAM
  • 1 TB SSD
₹70,990₹90,990
Buy now
NEXT ARTICLE BEGINS